CVE WATCH / VULNERABILITY DETAIL
CVE-2026-92989
MEDIUMCVSS 4.3NVD feed
Published 9 October 2026 · tracked since 10 October 2026
Description
The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107804 MEDIUM 5.3
- CVE-2026-107805 HIGH 7.5
- CVE-2026-105278 CRITICAL 9.8
- CVE-2026-104081 HIGH 8.1
- CVE-2026-94067 HIGH 8.1
- CVE-2026-94064 HIGH 8.8
- CVE-2026-94065 HIGH 8.8
- CVE-2026-100730 CRITICAL 9.8
- CVE-2026-94062 HIGH 8.1
- CVE-2026-62028 MEDIUM 5.4